NewsCryptoHackers Exploit macOS Screen Sharing Flaw to Secretly Mine Monero

Hackers Exploit macOS Screen Sharing Flaw to Secretly Mine Monero

Author: DailyCoin·

Key Takeaways

  • NCSC-NL confirmed on August 13 that attackers are actively exploiting CVE-2026-65400 in macOS Screen Sharing.
  • The flaw lets a network attacker bypass authentication, gain root-level access, and install a Monero miner.
  • Apple released emergency fixes on August 6 for macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.
  • Researchers at Huntress said changing passwords or removing accounts does not block the underlying vulnerability, and patching or disabling Screen Sharing is required.
  • Huntress found tens of thousands of potentially vulnerable internet-exposed hosts tied to hosted bare-metal Mac services.
Hackers Exploit macOS Screen Sharing Flaw to Secretly Mine Monero

Hackers are exploiting a newly patched flaw in Apple's macOS Screen Sharing feature to take control of vulnerable computers and secretly mine Monero, according to the Netherlands' National Cyber Security Centre (NCSC-NL). The agency confirmed on August 13 that attackers are actively exploiting the vulnerability, tracked as CVE-2026-65400.

The flaw allows attackers to bypass authentication in macOS Screen Sharing and gain high-level access to affected Macs, which they can then use to install cryptocurrency-mining malware. The attack is a form of cryptojacking: instead of stealing cryptocurrency from a wallet or exchange, criminals hijack someone else's computing power and use it to generate crypto. Because the mining runs in the background, it is often noticed only through its side effects rather than any obvious sign of intrusion.

Apple released an emergency security update on August 6, but Macs that have not been patched — particularly those with Screen Sharing exposed directly to the internet — remain at risk.

How the Attack Works

The vulnerability affects screensharingd, the macOS component responsible for the operating system's built-in remote-access feature. The flaw lets a network-based attacker get past Screen Sharing's normal authentication checks without valid credentials. Once access is obtained, attackers can gain root-level control of the Mac and install additional software. Although every compromise NCSC-NL observed involved mining, that level of access is not inherently limited to it.

NCSC-NL said that in every compromise it observed, attackers installed a Monero miner on the affected machine.

Security researchers at Huntress also found that common attempts to secure Screen Sharing, such as changing the password or removing authorized accounts, do not prevent exploitation of the underlying vulnerability. Closing the attack path requires patching the operating system or disabling Screen Sharing entirely.

Huntress noted that the risk is compounded by the rise of hosted bare-metal Mac services, such as cloud-based Mac minis, which often ship with Screen Sharing enabled by default. A search on the internet-scanning platform Censys turned up tens of thousands of potentially vulnerable hosts tied to such providers, according to Huntress. Mining campaigns of this kind have historically been documented far more often on Windows and Linux systems, so a remotely exploitable macOS flaw paired with a large pool of internet-exposed hosts stands out from the usual pattern.

Apple's fixes cover macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9.

Why Monero?

Monero (XMR) can be mined using general-purpose computer processors. XMR uses a proof-of-work algorithm called RandomX, which is designed to run on general-purpose CPUs rather than the specialized mining hardware commonly used to mine Bitcoin and some other cryptocurrencies.

For attackers, this can reduce the cost of running a mining operation. Instead of purchasing and operating their own hardware, they can use the computing power and electricity of their victims to mine Monero.

Monero also has privacy features designed to obscure the identities of parties to transactions, making some transactions more difficult to trace. Those features have drawn increased regulatory scrutiny in some jurisdictions, particularly in the context of anti-money-laundering measures.

Why This Matters

Attackers can use victims' Macs and electricity to mine crypto, shifting the cost of the mining operation onto the victim. The extra CPU usage can also slow the affected computer and increase its energy consumption. The remedy is narrow and clear: install Apple's August 6 update or disable Screen Sharing entirely, and verify that the feature is not reachable from the internet in the first place. For hosted Mac services, that check falls to the provider as much as the customer. With NCSC-NL confirming active exploitation within a week of the patch's release, the remaining exposure sits with unpatched machines — particularly the tens of thousands of internet-reachable hosts Huntress identified.